Back to skill

Security audit

网文创作流水线

Security checks across malware telemetry and agentic risk

Overview

This is mostly a local novel-writing workflow, but it should be reviewed carefully because it explicitly steers AI-detection evasion, strict author-style imitation, and broad auto-activation.

Install only if you want this skill to guide long-form Chinese web-novel production and are comfortable managing its broad triggers. Use it for original fiction and editing quality, not for concealing AI authorship from platforms or imitating an identifiable author's voice. The local scripts appear limited to project scaffolding and chapter checks, but review generated files before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The file instructs creating and then using a '写作风格分析报告.md' derived from an original author's traits and says later writing should strictly follow that report. Even though the document includes anti-plagiarism language elsewhere, this workflow operationalizes style imitation and can steer the agent toward producing derivative text that mimics living or recognizable authors beyond general novel-writing assistance.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the model to add '人工修改特征' and '降低AI检测率', which goes beyond ordinary prose improvement and enters AI-detection evasion. That makes the skill capable of helping users disguise machine-generated content as human-authored work, enabling deception in academic, publishing, platform-compliance, or spam contexts.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are very broad and match common, non-specialized writing requests such as '大纲', '续写', or '写小说'. This can cause the skill to auto-activate in situations where the user did not intend to invoke this workflow, leading to prompt hijacking of generic writing tasks and unnecessary exposure of the model to the skill’s steering instructions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The '什么时候用' section defines activation conditions in broad thematic terms covering many ordinary fiction-writing scenarios, without negative boundaries or disambiguation rules. In an agent environment, this increases the chance of unintended invocation and can let the skill override more appropriate general-purpose behavior for routine requests.

Vague Triggers

High
Confidence
98% confidence
Finding
The passive auto-load rule instructs activation whenever broad writing-related intent is detected, which is a classic overbroad routing condition. If exploited operationally, this can cause the skill to seize control of many unrelated prompts, inject extensive workflow constraints, and increase the chance of unintended file operations or context pollution across user sessions.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The requirement to '明确原作者的写作特征和禁忌' and '严格遵循风格报告中的要求' effectively hard-codes compliance with a specific author's style. That can override normal user choice about tone, language variety, or originality and increases the chance of unauthorized stylistic mimicry, especially in a skill explicitly designed for large-scale serialized fiction production.

Ssd 2

Medium
Confidence
96% confidence
Finding
These instructions semantically direct paraphrasing and stylistic alteration specifically to obscure AI-generation patterns, not merely to improve readability. This is dangerous because it operationalizes evasion of downstream AI-origin detection and content-governance systems, increasing the plausibility of deceptive mass-produced text.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.